Improperly implemented security check for standard in Junos OS - CVE-2023-44181

 

Improperly implemented security check for standard in Junos OS - CVE-2023-44181

Published: October 18, 2023


Vulnerability identifier: #VU82231
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44181
CWE-ID: CWE-358
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improperly implemented security check for standard error in storm control when Storm control is enabled and ICMPv6(internet control message protocol) packets are present on device. A remote non-authenticated attacker can perform a denial of service (DoS) attack.


Affected software

Junos OS

How to mitigate CVE-2023-44181

Install updates from vendor's website.

Junos OS - addressed in versions 20.2R3-S6, 20.3R3-S5, 20.4R3-S5, 21.1R3-S4, 21.2R3-S3, 21.3R3-S2, 21.4R3, 22.1R3, 22.2R2, 22.3R1

External References

Related Security Bulletins